A widespread campaign is delivering the Atomic (AMOS) infostealer to macOS users through fake GitHub repositories impersonating popular software. Attackers use SEO to promote these repositories, which instruct users to run terminal commands that install the malware. LastPass and other security teams are actively disrupting the campaign, but new repositories continue to appear.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Analysis of the fake software sites showed they were distributing Atomic macOS Stealer (AMOS), an infostealer capable of stealing credentials and other sensitive data from infected Macs. Reporting highlighted that the malware could be installed through deceptive download flows that bypass normal user trust expectations.
Security researchers uncovered a campaign using phony GitHub Pages sites impersonating software brands such as LastPass, Malwarebytes, and other password managers to target macOS users. The sites were designed to trick victims into downloading trojanized installers.
6 references tracked. Mallory keeps watching after this page renders.
malwarebytes.com
Open sourcearstechnica.com
Open sourcebleepingcomputer.com
Open sourcebleepingcomputer.com
Open sourcedarkreading.com
Open sourcehelpnetsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.